Skip to content
AISec Study

Closing the Gap in Enterprise AI Security

Findings from a structured, interview-based study of AI security and governance across 10 organizations, scored against a common catalog of 64 activities.

The AISec Study documents what AI security programs actually do, based on confidential interviews with the people running them.

UltraViolet Cyber sat down with security, AI, governance, and engineering leaders at 10 organizations across banking, enterprise software, healthcare, manufacturing, hospitality, government, and the nonprofit sector. Each organization was scored against a shared catalog of 64 activities across three domains: Direction & Oversight, Engineering & Usage, and Assurance & Protection. Every activity lands in one of three tiers: Established, Emerging, or Unobserved.

The result is a comparable, evidence-based view of AI security maturity across the data pool.

StrategyVisibilityGov & PolicyModel LifecycleAI SDLCAI SecOpsData GovernanceSecurity AssuranceRuntime MonitoringIncident Response
Data-pool averageRange across the 10 organizations (min and max)


What's in the report:

  • Full capability and domain-level scores across all 10 organizations in the data pool
  • The breadth-versus-depth gap, and what it means for where programs are actually exposed
  • Findings on AI coding assistant governance and agent identity, the two areas with the widest gap between adoption and control
  • A practitioner's view from Aravind Venkataraman, UltraViolet Cyber, on where the data points next
AISec Study Report